Skip to content

chore(deps): Pin workflow actions to commit SHAs []#169

Merged
Charles Hudson (phobetron) merged 1 commit intocontentful:mainfrom
linuxoptics:chore/pin-workflow-deps
Mar 10, 2026
Merged

chore(deps): Pin workflow actions to commit SHAs []#169
Charles Hudson (phobetron) merged 1 commit intocontentful:mainfrom
linuxoptics:chore/pin-workflow-deps

Conversation

@linuxoptics
Copy link
Copy Markdown
Contributor

  • Pin actions to commit SHAs to follow Github best practices.

@phobetron
Copy link
Copy Markdown
Collaborator

Alex Olea (@linuxoptics) is there an automated tool that will scan for these SHAs and determine:

  • whether any security issues may be found at a later date related to these SHAs?
  • whether they may be safely updated?
  • to what new SHAs they could be safely updated?

I'm a bit hesitant to move from version numbers to SHAs as long as simply moving to SHAs may give us a false sense of security and stability unless we also have adequate supporting tooling.

@phobetron Charles Hudson (phobetron) merged commit 89d6477 into contentful:main Mar 10, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants